Operation Manual

Examples for IP Filter Profiles
59 NT/MPRI – 4 Special NT/MPRI Settings
These profiles can be used without modification for a standard Internet
connection. They will protect your network reliably from outside ac-
cess, while allowing users in the local network to access Internet serv-
ers. The two profiles can be used in the scenarios described above, for
example.
In the filter profile “Internet incoming”, a number of rules have the
statuts “disabled” while others are “enabled”. All rules which prevent
access to your LAN initiated from outside are enabled. Rules that are
“disabled” are pre-configured for cases in which such services as the
company ftp server, web server or e-mail server are to be made avail-
able for access from the Internet. To allow outside access to such addi-
tional services, the filter profile must be edited accordingly before it is
selected in the configuration of your Internet call destination.
Note the following for both of these lists:
l All the rules in both profiles have been created with the broadest
possible criteria for the descriptive categories “Source” and “Call
Destination”: the source of the packet can be any host (the criteri-
on for the source in each rule is thus: 0.0.0.0 / 0), as can the call
destination (destination criterion in each rule is thus: 0.0.0.0 / 0).
For the sake of legibility this information was not repeated for
each rule in the following list.
l All rules contain the entry “No Log”. This information also has
been omitted from the list for better legibility.
ntmpri-e.book Seite 59 Donnerstag, 28. Februar 2002 11:26 11